Skip to main content
Kyle Grinstead (Forter) a posé une question dans #Automation

We are a bit unique in that we currently are using a custom-built Global Action button for our web-to-case submissions, as opposed to a standard Community form. We have recently experienced a large amounts of web-to-case SPAM attacks, so I was curious if anyone has experienced something similar to this situation, and what resolutions anyone has found.

1 réponse
  1. Hier, à 14:01

    Hi Kyle,

    For Web-to-Case spam, a few things are worth checking:

    • Enable reCAPTCHA for the Web-to-Case form if your setup supports it.
    • Make sure Require reCAPTCHA Verification is enabled in the Web-to-Case settings.
    • Add server-side validation/rules to reject obvious spam based on email, subject, or other known patterns.
    • Consider using a honeypot field or similar bot-detection approach if you're using a custom form.
    • Review the source/IP patterns in the incoming Cases to identify common characteristics of the spam.
    • If you're using a custom Global Action, verify that it isn't bypassing protections that would normally be present in the standard Web-to-Case flow.

    Since your submission mechanism is custom-built, the exact solution will depend on how the action is generating the Case. If you can share the Global Action/LWC or Apex implementation and how the Community user submits the request, that would help narrow it down. 

0/9000